Downer Enhances Security Protocols to Address Increasing Contract Requirements
We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!
Quick Read
- Downer Group boosts cybersecurity protocols to satisfy contract specifications.
- Invested in ThreatLocker endpoint security to improve application management and regulate privileged access.
- Adherence to “maturity level two requirements” within the Essential Eight is now essential for contractual agreements.
- Minimizing local admin rights greatly improves security.
- ThreatLocker enables standard users to operate certain applications with admin privileges securely.
Downer Group’s Cybersecurity Transformation
As the necessity for rigorous cybersecurity in bids increases, Downer Group has strategically allocated resources to ThreatLocker endpoint security. This strategy is part of a comprehensive effort to improve application oversight and manage privileged access with efficiency. The initiative was prompted by the requirement to meet particular security standards in emerging contracts, especially the “maturity level two requirements” as outlined in the Essential Eight framework.
Addressing Contractual Security Requirements
Aidan Turner, head of security engineering and platforms at Downer, noted a marked change in clients’ expectations regarding cybersecurity. While discussions about zero trust and cybersecurity were rare five to ten years ago, they are now fundamental to securing bids and meeting contractual requirements.
Adopting ThreatLocker
The decision to invest in ThreatLocker was not a reaction to any particular incident but rather a proactive step towards fulfilling compliance requirements. The implementation of ThreatLocker has enabled a decrease in local admin rights, an important factor in bolstering cybersecurity protocols across the organization.
Overseeing Privileged Access
Turner emphasized that the organization has significantly decreased the number of users with administrative access. In the past, over 1000 users had this access, but with ThreatLocker’s elevation control module, this has been reduced to under 100. This tool permits users to run essential applications with administrative rights without full control, preserving security integrity.
Conclusion
Downer Group has markedly strengthened its cybersecurity framework by implementing ThreatLocker endpoint security. This decision is in response to the rising demands in the bidding processes that necessitate robust security measures like those found in the Essential Eight. By proficiently managing application control and privileged access, Downer guarantees compliance and security across its varied operations.
Reader questions
Frequently asked questions
Fast answers to the questions readers ask most about Downer Enhances Security Protocols to Address Increasing Contract Requirements.
Why did Downer Group choose to invest in ThreatLocker?
The investment was aimed at meeting increasing cybersecurity standards in tenders and contracts, especially under the Essential Eight framework.
What effect has ThreatLocker had on Downer's admin permissions?
ThreatLocker has allowed Downer to greatly cut down on local admin permissions, improving overall security.
What constitutes the Essential Eight requirements?
The Essential Eight is a collection of cybersecurity methodologies endorsed by the Australian Cyber Security Centre to assist organizations in mitigating cyber risks.
Was there a particular incident that led to the adoption of ThreatLocker?
No specific incident triggered the implementation; it was a calculated decision for compliance and risk management purposes.
How does ThreatLocker's elevation control feature benefit Downer?
It enables standard users to execute applications with necessary permissions without granting excessive authority, ensuring security while supporting operational efficiency.
